Falhas do tipo CWE-416

5.043 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar (ler ou escrever) um bloco de memória que já foi liberado (free, delete). O programa mantém um ponteiro para a memória, mas o sistema operacional pode reatribuir essa região para outro uso, causando corrupção de dados, travamento ou execução de código arbitrário.

Exemplo

Um servidor web aloca memória para armazenar dados de sessão do usuário, depois libera essa memória quando a sessão encerra. Se uma thread continuar tentando acessar essa sessão após a liberação, pode ler dados de outra sessão ou sobrescrever dados críticos de outro processo.

Como mitigar

Sempre anule ponteiros após liberar memória (ptr = NULL), use variáveis de controle para rastrear estado de alocação, implemente gerenciamento automático de memória quando possível (smart pointers em C++), e execute testes com sanitizers (AddressSanitizer, Valgrind) durante desenvolvimento e CI/CD.

CVE-2026-43632CRITICALllama.cpp b7492–b9060 Use-After-Free in Tokenization EndpointsEPSS 0.5%CVE-2022-3586MEDIUMA flaw was found in the Linux kernel’s networking code. A use-after-free was found in the way the sch_sfb enqueue function used the socket bEPSS 0.5%CVE-2023-21680HIGHWindows Win32k Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2026-26311MEDIUMEnvoy HTTP: filter chain execution on reset streams causing UAF crashEPSS 0.5%CVE-2025-0634MEDIUMUse After Free vulnerability in Samsung Open Source rLottie allows Remote Code Inclusion.This issue affects rLottie: V0.2.EPSS 0.5%CVE-2025-54588HIGHEnvoy: Race condition in Dynamic Forward Proxy leads to use-after-free and segmentation faultsEPSS 0.5%CVE-2025-26648HIGHWindows Kernel Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2025-62229HIGHXorg: xmayland: use-after-free in xpresentnotify structure creationEPSS 0.5%CVE-2025-4372HIGHUse after free in WebAudio in Google Chrome prior to 136.0.7103.92 allowed a remote attacker to potentially exploit heap corruption via a crEPSS 0.5%CVE-2026-8336HIGHPost-authentication use-after-free error in $_internalJsEmit and mapreduce commandsEPSS 0.5%CVE-2023-30772MEDIUMThe Linux kernel before 6.2.9 has a race condition and resultant use-after-free in drivers/power/supply/da9150-charger.c if a physically proEPSS 0.5%CVE-2026-20870HIGHWindows Win32 Kernel Subsystem Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2022-41222HIGHmm/mremap.c in the Linux kernel before 5.13.3 has a use-after-free via a stale TLB because an rmap lock is not held during a PUD move.EPSS 0.5%CVE-2023-42041HIGHPDF-XChange Editor Annotation Use-After-Free Remote Code Execution VulnerabilityEPSS 0.5%CVE-2026-23884HIGHHeap-use-after-free in gdi_set_boundsEPSS 0.5%CVE-2026-23883HIGHHeap-use-after-free in update_pointer_newEPSS 0.5%CVE-2026-2789HIGHUse-after-free in the Graphics: ImageLib componentEPSS 0.5%CVE-2026-2787HIGHUse-after-free in the DOM: Window and Location componentEPSS 0.5%CVE-2024-5847HIGHUse after free in PDFium in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafEPSS 0.5%CVE-2024-5846HIGHUse after free in PDFium in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafEPSS 0.5%